Lucene search

K
hiveproHiveForce LabHIVEPRO:E97E67D35594D6475CCB415ADE5C2ADB
HistoryDec 12, 2022 - 5:43 a.m.

Fortinet addresses Authentication Bypass in addition to numerous flaws

2022-12-1205:43:13
HiveForce Lab
www.hivepro.com
32
fortinet
authentication bypass
fortios
fortiproxy
vulnerability
remote attacker
access-challenge
radius
http request

EPSS

0.002

Percentile

57.5%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary Fortinet addressed security flaws across its products, including a high-severity authentication bypass affecting FortiOS and FortiProxy tracking CVE-2022-35843 in FortiOS's SSH login component. Only when Radius authentication is utilized can the bug be triggered. A remote attacker can circumvent authentication and get access to the device by delivering a specially designed Access-Challenge response from the Radius server. Other weaknesses allow an authenticated attacker to retrieve files and execute arbitrary code via crafted HTTP requests.

EPSS

0.002

Percentile

57.5%

Related for HIVEPRO:E97E67D35594D6475CCB415ADE5C2ADB